>> Sun Java Runtime Environment Font Parsing Remote Command Execution
Title : Sun Java Runtime Environment Font Parsing Remote Command Execution VUPEN ID : VUPEN/ADV-2007-2910 CVE ID : CVE-2007-4381
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-17
Technical Description
A vulnerability has been identified in Sun JRE, JDK and SDK, which could be exploited by attackers to take complete control of an affected system. This issue is caused by an error in the font parsing code, which could be exploited by a malicious applet to grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.